
Risky Business Risky Business #830 -- LiteLLM and security scanner supply chains compromised
35 snips
Mar 25, 2026 Braden Rogers, Chief Customer Officer at Island, helps companies govern employee use of AI while preventing data leaks. He discusses browser-based DLP, tenancy challenges with AI providers, and routing the right model to the right user. Short, sharp takes on preventing sensitive data from being pasted into chatbots and balancing executive access with data safety.
AI Snips
Chapters
Transcript
Episode notes
LLMs Controlling Desktops Will Redefine Acceptable Risk
- Anthropic released a product that lets Claude control a user's computer (remote agent + cloud orchestration), expanding the attack surface from API calls to full desktop actions.
- Hosts warned this will be widely used and "good enough" security will become the de facto standard.
Always Confirm Official Sources Before Installing AI Tools
- Verify official download sources before installing AI tooling to avoid malicious SEO and fake installers that deliver shells.
- Patrick flagged malicious Google ads and fake Claude/Claw download pages that were installing remote shells.
High-End iOS Exploits Are Becoming Commodity Kits
- Multiple advanced iOS exploit kits (Karuna, Darksword) are resurfacing in secondary markets and being reused as commodity tools targeting wallets and Ukrainian users.
- Researchers see code forks and bolt-ons indicating the kits are sold/shared then modified by different operators.
